
VMware, Inc. 19
4
AfterESXhostpreparationiscomplete,youcansecureinternalnetworksbyinstallingavShieldEdge.Ifyou
areinstallingvShieldEdgeinstancesonvDSportgroups,youcanisolatethoseportgroupsbyenablingPort
GroupIsolationoneachvDS.
Thischapterincludesthefollowingtopics:
“EnablingPortGroupIsolation”onpage 19
“InstallingavShieldEdge”onpage 21
Enabling Port Group Isolation
PortGroupIsolationcreatesabarrierbetweenthevirtualmachinesprotectedbyavShieldEdgeandthe
externalnetwork.WhenyouenablePortGroupIsolationandinstallavShieldEdgeonavDSportgroup,you
isolateeachsecuredvDSportgroupfromtheexternalnetwork.WhenPortGroupIsolationis
enabled,traffic
isnotallowedaccesstothevirtualmachinesinthesecuredportgroupunlessNATrulesorVLANtagsare
configured
To enable Port Group Isolation on a vDS
1EnablePortGroupIsolationoneachvDS.
2InstallavShieldEdgeoneachvDSportgroupyouplantosecure.
3MovethevirtualmachinestosecuredvDSport
groups.
vNetwork Preparation and vShield
Edge Installation
4
IMPORTANTIfyouintendtousethePortGroupIsolationfeature,youshouldinstallPortGroupIsolationon
allESXhostsinyourvCenterenvironmentbeforeyouinstallanyvShieldEdgevirtualmachines.Ifyoudonot
installPortGroupIsolationandattempttoenablethefeatureduringvShieldEdgeinstallation,
PortGroup
Isolationdoesnotwork.See“InstallvShieldApp,vShieldEndpoint,andPortGroupIsolationServicesonan
ESXHost”onpage 15.
I
MPORTANTAllvShieldRESTrequestsrequireauthorization.Youcanusethefollowingbasicauthorization:
Authorization: Basic YWRtaW46ZGVmYXVsdA==
YWRtaW46ZGVmYXVsdA==representstheBase64encodingofthevShieldManagerdefaultlogincredentials
(admin:default).
NOTEPortGroupIsolationisanoptionalfeaturethatisnotrequiredforvShieldEdgeoperation.PortGroup
IsolationisavailableforvDS‐basedvShieldEdgeinstallationsonly.
Komentáře k této Příručce